Advertisement
Open-Source Android AI Agent Hijacking Leads to Host System RCE
Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.
RedHook Android Malware: Abusing Wireless ADB for Local Shell Access
RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.
Google Gemini Hijack: Command Injection via Messaging Notifications
Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.
Google Gemini Hijacked on Android via Poisoned Notifications
Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.
Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626
CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.
CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595
CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.
Advertisement
CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day
Google's June 2026 security update fixes 124 vulnerabilities, including CVE-2025-48595, a zero-day privilege escalation flaw under active exploitation.
Misconfigured MSAL for Android Exposes Microsoft Account Tokens
A vulnerability in the Microsoft Authentication Library for Android allowed unauthorized apps to intercept OAuth tokens, impacting billions of users.
Android Intrusion Logging: Enhancing Spyware Forensics for High-Risk Users
Google introduces Intrusion Logging for Android to capture persistent forensic data, aiding the detection of sophisticated spyware and state-sponsored attacks.
7.3M Downloads: Analyzing Fraudulent Android Call History Apps
Researchers discover 28 fraudulent Android apps on the Google Play Store that trick millions of users into expensive, fraudulent subscriptions.
Google Android Binary Transparency: Defending Against Supply Chain Attacks
Google expands Binary Transparency to Android apps, providing a public ledger to verify app integrity and mitigate risks of mobile supply chain attacks.
Google Android VRP 2024 Updates: $1.5M for Pixel Kernel Exploits
Google overhauls its Vulnerability Rewards Programs, increasing payouts for complex Android exploits while devaluing bugs easily identified by AI tools.
Google Adjusts Bug Bounties: $1.5M Android Reward and AI Shift
Google updates its Vulnerability Reward Program, increasing Android zero-click payouts to $1.5 million while adjusting Chrome rewards amid an AI security surge.
EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass
A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.
Exposed Google API Keys in Android Apps Grant Gemini Access
Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.
ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, & Cloud Evasion
Analysis of the latest ThreatsDay Bulletin covering critical pre-authentication exploit chains, stealthy Android rootkits, and advanced CloudTrail evasion techniques.
Android Security Safeguards and UK Cyber Reporting Mandates
Analysis of new Android live threat detection features, the Operation Alice takedown, and updated UK cybersecurity reporting regulations for 2024.
Google VRP 2025: $17.1 Million Paid for Security Vulnerabilities
Google's Vulnerability Reward Program paid a record $17.1 million in 2025, highlighting critical security research trends in Android, Chrome, and AI systems.